Inherent risk and residual risk: definitions and calculation

What your risks are worth before and after security controls, how to calculate it, and who must accept what is left.

· 9 min read
Illustration: a five-by-five grid whose top-right corner glows orange

Residual risk is the risk that remains once security controls are applied; inherent risk is the risk you would face with no controls at all. Comparing the two shows what your controls really achieve, and it is residual risk, not inherent risk, that management must knowingly accept.

01

Inherent risk: risk without any controls

Inherent risk, also called gross risk, is the risk level of a scenario before the organisation takes any action to reduce it. The glossary of NIST, the US National Institute of Standards and Technology, uses the definition from the COSO enterprise risk management framework: the risk to an entity in the absence of any direct or focused action by management to alter its severity.

In practice, you ask: “if we had nothing in place, what would happen and how likely is it?”. For an accounting firm that keeps its clients' files on a file server, the scenario “ransomware encrypts the server and its backups at the height of tax season” has maximum severity and, without specific protection, very high likelihood. On scales from 1 to 4, it scores 4 x 4 = 16.

Rating inherent risk may seem theoretical, since no organisation starts from scratch. It is still useful for two reasons: it highlights the scenarios that would be catastrophic if a control failed, and it lets you measure what each control contributes. A high inherent risk brought down to a low residual risk points to a critical control that needs close monitoring.

02

Residual risk: what remains after treatment

Residual risk is defined by ISO Guide 73:2009, long the reference risk management vocabulary (since replaced by ISO 31073:2022), and by the 2018 edition of ISO/IEC 27000, the information security vocabulary, as the risk remaining after risk treatment. Both add two notes: residual risk can contain unidentified risk, and it can also be known as “retained risk”. NIST describes it as the portion of risk remaining after security measures have been applied.

Three points follow. First, residual risk is never zero: no control removes a threat entirely, short of giving up the activity. Second, it depends on controls that are actually in place and effective, not those in next year's budget. Third, it includes an unknown part, which is why the analysis must be reviewed regularly.

03

Inherent risk vs residual risk: the differences

CriterionInherent riskResidual risk
WhenBefore any controlAfter controls are applied
QuestionWhat are we exposed to if nothing is done?What are we still exposed to today?
UseSpot the most severe scenarios and critical controlsDecide: accept, or keep treating
Also calledGross riskNet risk, retained risk
Validated byThe analysis team, with business unitsThe risk owner, through formal acceptance

Risk treatment sits between the two. ISO 27005 describes four options: reduce the risk with controls, avoid it by giving up the activity that exposes you, share it (insurance, outsourcing) or retain it knowingly. Our article on the ISO 27005 standard details this process.

04

How to calculate residual risk

There is no official formula: neither ISO 27005 nor EBIOS Risk Manager imposes a scale. The most common approach, and the easiest to defend in front of an auditor, is to re-rate the scenario taking controls into account. It takes four steps.

  • Rate the inherent risk. Estimate the severity of consequences and the likelihood of the scenario without controls, then combine them, often as a product on a risk matrix.
  • List existing controls. For each scenario, list the controls that act on it. A control works either on likelihood (it makes the attack harder) or on severity (it limits the damage), sometimes on both.
  • Check that they work. A declared control is not an applied control. A backup that has never been restored, or multi-factor authentication that leaves out admin accounts, should not lower the rating.
  • Re-rate and justify. The new severity-likelihood pair gives the residual risk. For every step gained, record the control that justifies it.

The diagram below uses the accounting firm example. Tick the controls and watch the dot move down the matrix: preventive controls slide it to the left (likelihood), protection and recovery controls move it down (severity).

Interactive diagram · severity x likelihood

Apply controls and watch the risk go down

Scenario: ransomware encrypts the file server and its connected backups.

Tick the controls one by one, or run the demo.

Security controls

16 Criticality 16 out of 16 (severity 4, likelihood 4)

Starting point: no control is taken into account.

Criticality, control after control

  1. 16Inherent risk

Teaching example with scales from 1 to 4 and criticality equal to severity x likelihood. With no controls, inherent risk is 16. Multi-factor authentication and patching bring likelihood down to 2 (criticality 8), offline backups bring severity down to 3 (criticality 6, threshold reached), the recovery plan brings it down to 2 (criticality 4). Insurance shares the risk without changing its rating.

What about formulas with an effectiveness percentage?

Some organisations calculate residual risk by multiplying inherent risk by a control coverage rate, for example “16 x (1 − 60%) = 6.4”. The method is quick, but it gives misleading precision: who can tell whether a control is 60% or 70% effective? It also hides what the controls actually are. If you use it, keep simple levels (none, partial, full) and describe what they mean. And remember that a sharing measure such as insurance does not change the likelihood of an attack: it moves part of its cost.

05

Accepting residual risk: who decides, and against which criteria

Calculating residual risk is not enough: someone has to decide to keep it. ISO/IEC 27001:2022 requires this explicitly. Clause 6.1.2 asks you to set risk acceptance criteria in advance, and clause 6.1.3 asks you to obtain the risk owners' approval of the treatment plan and their acceptance of residual risks. Since the 2022 edition, ISO 27005 also presents acceptance as a decision taken at the end of treatment rather than a separate stage.

The EBIOS Risk Manager method, published by ANSSI, the French national cybersecurity agency, takes the same line. Its workshop 5, on risk treatment, aims to identify residual risks and set up the framework for monitoring them; according to ANSSI's guide, it produces a summary of residual risks. In the French public sector, this summary feeds the security accreditation file, and the accreditation authority accepts residual risks when it signs the decision.

A useful acceptance has four elements

  • A level: the residual rating and the criterion it is compared with.
  • An identified decision-maker: the risk owner, who has the authority to commit resources.
  • A justification: why going further is not reasonable today (cost, time, business constraint).
  • A deadline: the date of the next review, or the event that will trigger it.
06

Residual risk within risk analysis

Inherent and residual risk shape every risk analysis. They appear in three places.

  • In the matrix. A single risk matrix can show each scenario twice, before and after treatment, with an arrow between the two. This is often the clearest view for an executive committee.
  • In the risk map. A risk map presented to management should always say whether it shows gross or net risks: they do not tell the same story.
  • In monitoring. Residual risk is not fixed. A control that degrades (an unapplied patch, a supplier that changes subcontractor, see our article on third-party risk management) pushes it back up. This is why monitoring is part of the ISO 27005 process.

Finally, rating severity depends on the security needs of what you protect. Stating them first, for example with the DICP criteria, makes inherent and residual ratings more consistent from one scenario to the next.

07

Common mistakes

  • Counting planned controls as done. Until it is deployed, a control does not lower residual risk. It belongs in the action plan, with a “target” residual risk.
  • Lowering everything by one notch. A control acts on a specific scenario. Email filtering reduces phishing, not a hosting provider outage.
  • Forgetting inherent risk. Without it, you cannot spot the controls whose failure would be catastrophic.
  • Accepting without a decision-maker. A high residual risk marked “accepted” in a spreadsheet, with no name or date, is not an acceptance.
  • Never reviewing the rating. Threats evolve: a risk accepted three years ago may no longer be acceptable.
08

How Phinasoft helps

In a spreadsheet, residual risk quickly becomes a column nobody updates. The Phinasoft risk analysis module links each analysis, whether run with EBIOS RM through a module labelled by ANSSI, with ISO 27005 or with your own method, to your action plan: the risk level changes as controls are implemented. Review and approval workflows formalise decisions, automatic reminders keep action plans moving, and each scope is reassessed from its previous version, which keeps the history of ratings. To see it on your own scenarios, you can request a demo.

Summary

01

Two snapshots of the same risk

Inherent risk is the level of a scenario with no controls at all; residual risk is what remains once controls are applied. The gap between the two shows how useful your controls are.

02

A simple calculation, explicit assumptions

First rate the raw scenario, then rate it again taking into account controls that are actually in place and effective. A reasoned re-rating beats an effectiveness percentage that gives false precision.

03

A decision, not a result

ISO 27001 requires risk owners to formally accept residual risk against criteria set in advance. EBIOS RM devotes its workshop 5 to assessing and monitoring it.

Frequently asked questions

What is residual risk?

It is the risk remaining after risk treatment, in other words once security controls have been applied. ISO Guide 73 and ISO/IEC 27000 (2018 edition) define it this way, noting that it can contain unidentified risk. It is never zero: the aim is to bring it below the level the organisation is prepared to accept.

What is inherent risk?

It is the risk level of a scenario in the absence of any action taken by the organisation to reduce it. The definition used by NIST, taken from the COSO enterprise risk management framework, refers to risk with no direct or focused action by management to alter its severity. It is also called gross risk.

How do you calculate residual risk?

First rate the inherent risk, for example severity x likelihood. Then list the controls in place and check that they work. Finally, re-rate severity and likelihood taking these controls into account: the product is the residual risk. Every reduction must be justified by a specific control.

Who accepts residual risk?

The risk owner, meaning the person with the authority and accountability to manage the risk, usually an executive or a business manager. ISO 27001 requires risk owners to approve the treatment plan and accept residual risks. In the French public sector, the accreditation authority does so when it accredits a system.

Can residual risk be above the acceptance threshold?

Yes, provided this is a conscious, reasoned and recorded decision. A control may be too expensive or take time. Management can then temporarily accept a high risk, with a dated action plan and a scheduled review. What is not acceptable is a high risk that nobody decided to keep.

What is the difference between residual risk and accepted risk?

Residual risk is a level: what remains after controls. Accepted risk is a decision: the risk owner commits to living with that level. A residual risk can be accepted or, if it exceeds the criteria, trigger a new treatment cycle.

A platform and service that adapt to you

Our platform is designed for fine-tuned configuration and broad adaptability to your needs.